TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Vulnerabilities in Password-Manager Apps

263 pointsby tobijklabout 8 years ago

21 comments

tptacekabout 8 years ago
A theme of this work is vulnerabilities in the &quot;internal browser&quot; some of the mobile password managers provide. Mobile password managers have internal browsers because it&#x27;s not easy to extend the standard mobile browsers, and password managers want to automate the entry of passwords into form fields.<p>Don&#x27;t use the internal browser of your password manager, no matter which one you use. There&#x27;s too much that can go wrong, and the small convenience just isn&#x27;t worth it.
评论 #13755148 未加载
评论 #13757040 未加载
评论 #13760078 未加载
AdmiralAsshatabout 8 years ago
So, all three of the LastPass issues have been fixed, and within two weeks of being reported, to boot:<p><pre><code> * 2016-08-22 Vulnerability Discovered * 2016-08-24 Vulnerability Reported * 2016-09-06 Vulnerability Fixed</code></pre>
评论 #13755192 未加载
评论 #13755569 未加载
评论 #13757128 未加载
Veloxabout 8 years ago
One of the 1Password ones (<a href="https:&#x2F;&#x2F;team-sik.org&#x2F;sik-2016-040&#x2F;" rel="nofollow">https:&#x2F;&#x2F;team-sik.org&#x2F;sik-2016-040&#x2F;</a>) about leaking URLs is marked as fixed, however, that&#x27;s a little misleading. It&#x27;s fixed if you use their newer vault format, which has limitations, and is <i>not</i> selected by default when you create a new vault. I wrote this about it a while back: <a href="https:&#x2F;&#x2F;myers.io&#x2F;2015&#x2F;10&#x2F;22&#x2F;1password-leaks-your-data&#x2F;" rel="nofollow">https:&#x2F;&#x2F;myers.io&#x2F;2015&#x2F;10&#x2F;22&#x2F;1password-leaks-your-data&#x2F;</a>
评论 #13756445 未加载
评论 #13757150 未加载
M_Greyabout 8 years ago
This is why I still go to the trouble of PGP encrypting a file with my passwords, rather than relying on a password manager. I keep wanting to switch, but damn it, I just can&#x27;t bring myself to have that much trust in them.<p>Edit: Thanks for the informative replies, the links, and the advice. I&#x27;m going to explore all of my options and re-think this.
评论 #13755081 未加载
评论 #13754910 未加载
评论 #13758874 未加载
评论 #13754948 未加载
评论 #13755144 未加载
评论 #13755022 未加载
评论 #13760389 未加载
kqr2about 8 years ago
Some older papers on security vulnerabilities of password managers:<p><a href="https:&#x2F;&#x2F;www.schneier.com&#x2F;blog&#x2F;archives&#x2F;2014&#x2F;09&#x2F;security_of_pas.html" rel="nofollow">https:&#x2F;&#x2F;www.schneier.com&#x2F;blog&#x2F;archives&#x2F;2014&#x2F;09&#x2F;security_of_p...</a><p>Any thoughts on Bruce Schneier&#x27;s PasswordSafe password manager?
评论 #13757239 未加载
评论 #13759535 未加载
评论 #13755957 未加载
评论 #13757342 未加载
SeriousMabout 8 years ago
What about enpass? That would be very interesting since they also promise to be very secure.
评论 #13755187 未加载
评论 #13754906 未加载
Sir_Cmpwnabout 8 years ago
Tangentally related:<p><a href="https:&#x2F;&#x2F;github.com&#x2F;SirCmpwn&#x2F;pass-rotate" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;SirCmpwn&#x2F;pass-rotate</a><p>I posted it on here the other day but it didn&#x27;t go far. It&#x27;s like youtube-dl but instead of downloading videos it changes your password on various online services. If you get your password compromised by vunlerabilities or whatnot it makes it easy to mass-rotate your passwords. Could use some help adding support for more websites if you&#x27;re interested.<p>&lt;&#x2F;shameless promo&gt;
toygabout 8 years ago
I looked at the LastPass ones (all for Android) and they look relatively minor. The only real wtf is <a href="https:&#x2F;&#x2F;team-sik.org&#x2F;sik-2016-022&#x2F;" rel="nofollow">https:&#x2F;&#x2F;team-sik.org&#x2F;sik-2016-022&#x2F;</a> - hardcoding keys should be a big nope. Still, it happens only if you use a PIN rather than your master password; I hope this does not happen in iOS if you use TouchID...?
评论 #13755251 未加载
评论 #13754925 未加载
评论 #13754684 未加载
cjCamelabout 8 years ago
Looks like all of the 1Password issues were discovered and fixed last September.
spullaraabout 8 years ago
I just use iCloud keychain. The third party ones can never be as secure. For non-safari usage a little less convenient but worth it.
评论 #13755357 未加载
评论 #13758076 未加载
bgentryabout 8 years ago
Site&#x27;s down. Text-only cached version at least lets you read some of the content: <a href="http:&#x2F;&#x2F;webcache.googleusercontent.com&#x2F;search?q=cache:kJ5Zk-7KPswJ:https:&#x2F;&#x2F;team-sik.org&#x2F;trent_portfolio&#x2F;password-manager-apps&#x2F;&amp;num=1&amp;hl=en&amp;gl=us&amp;prmd=ivn&amp;strip=1&amp;vwsrc=0" rel="nofollow">http:&#x2F;&#x2F;webcache.googleusercontent.com&#x2F;search?q=cache:kJ5Zk-7...</a>
评论 #13754712 未加载
Globzabout 8 years ago
We need the same kind of investigation for iOS, this kind of research was so much needed because after all this is where we store all of our entire internet identities, good job!
jquastabout 8 years ago
Just my brief experience of 2-3 hours with LastPass today. Broken javascript errors when trying to import. Searched for customer support, couldn&#x27;t find any! How do I file bugs? Sign up and post to their web forum?<p>I noticed their website is made entirely in php. Not that php is bad, but this is possibly the worst choice for a web platform that holds secrets. At only $12 a year, they probably aren&#x27;t trying very hard.
评论 #13762947 未加载
评论 #13760190 未加载
JimAabout 8 years ago
Anyone seen anything similar on Roboform? Been using them for years but I wonder how much vulnerability testing it has gotten.
circaabout 8 years ago
I have moved from LastPass to Dashlane and rarely have issues. Its been fairly solid for me the past year or so. Anyone had issues with Dashlane?
评论 #13758279 未加载
andybakabout 8 years ago
Avast are still working on vulnerabilities reported in November 2016. They seem by far the least responsive of the apps mentioned.
jamesdwilsonabout 8 years ago
<a href="https:&#x2F;&#x2F;ssl.masterpasswordapp.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;ssl.masterpasswordapp.com&#x2F;</a>
no_wizardabout 8 years ago
shocked I didn&#x27;t&#x27; see bitwarden in here?<p>I use Bitwarden for some things (lots of testing, nothing serious). Given its OSS nature, i thought it might have had more traction.<p>For reference: <a href="https:&#x2F;&#x2F;github.com&#x2F;bitwarden" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;bitwarden</a>
chjabout 8 years ago
Too bad 1Password doesn&#x27;t encrypt title and URLs.
tehabeabout 8 years ago
Password Safe is missing …
jonduboisabout 8 years ago
Not surprising. Password manager give you convenience at the expense of security.
评论 #13761462 未加载